Enable customer-managed encryption keys
By default, cloud providers encrypt machine disks with a key that the provider manages. Configuring a compute machine set to use a customer-managed encryption key gives you control over the key’s lifecycle, and therefore over access to the data on those disks.